Executive Order 13800: Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

US FederalGovernment & Public Sector2017
ByDecipherU Editorial

EO 13800 directed federal agencies to use the NIST Cybersecurity Framework (CSF) for managing cybersecurity risk. This cybersecurity executive order held agency heads accountable for risk management and required agencies to submit risk assessments to OMB and DHS. It also addressed workforce development, calling for assessments of cybersecurity education needs.

Quick Reference

EnactedMay 11, 2017
Enforcement BodyOMB, DHS, agency heads
PenaltiesAgency heads personally accountable for cybersecurity risk management
Applicable ToFederal executive branch agencies

Key Requirements

Section 1(b)

Agency heads must use the NIST Cybersecurity Framework to manage cybersecurity risk within their enterprises

Section 1(c)

Each agency must provide a risk management report to OMB and DHS within 90 days

Section 3(d)

Commerce and DHS must assess the scope and sufficiency of efforts to educate and train the cybersecurity workforce

How Does EO 13800 Affect Cybersecurity Careers?

This executive order designated the NIST CSF as the standard risk management framework for federal cybersecurity. GRC analysts implementing NIST CSF in government agencies work under this mandate. The workforce development provisions helped expand funding for cybersecurity education and training programs.

Cybersecurity Roles That Work With EO 13800

Related Cybersecurity Certifications

Related Cybersecurity Laws

Frequently Asked Questions

What is EO 13800 in cybersecurity?

EO 13800 directed federal agencies to use the NIST Cybersecurity Framework (CSF) for managing cybersecurity risk. This cybersecurity executive order held agency heads accountable for risk management and required agencies to submit risk assessments to OMB and DHS. It also addressed workforce development, calling for assessments of cybersecurity education needs.

How does EO 13800 affect cybersecurity careers?

This executive order designated the NIST CSF as the standard risk management framework for federal cybersecurity. GRC analysts implementing NIST CSF in government agencies work under this mandate. The workforce development provisions helped expand funding for cybersecurity education and training programs.

What are the penalties for EO 13800 non-compliance?

Agency heads personally accountable for cybersecurity risk management

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?